wmmon32.exe - Dangerous

wmmon32.exe

Jeff's Story:

My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.

I sought a solution on the Internet and discovered your product and tried out the trial.

You quickly found the rootkit and SAVED my PC!

I haven't had any problems since, and I'm extremely grateful.

Manual removal instructions:

wmmon32.exe
W32/Agobot-KQ is an IRC backdoor Trojan and network worm.
It is capable of spreading to computers on the local network protected by weak passwords.
When first run it copies itself to the Windows system folder as wmmon32.exe and creates the following registry entries to run itself on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\WSSAConfiguration = wmmon32.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\WSSAConfiguration = wmmon32.exe

Each time W32/Agobot-KQ is run it attempts to connect to a remote IRC server and join a specific channel.
Runs continuously in the background, allowing a remote intruder to access and control the computer via IRC channels.
Attempts to terminate and disable various anti-virus and security-related programs.

You can automatical remove it from startup with RegRun Startup Optimizer.

Remove wmmon32.exe now!